Skip to content

PLY1 Protocol Specification

The PLY1 protocol specifies the exact binary layout for embedding steganographic data within ISO/IEC 18004 Model 2 QR symbols.


A standard QR symbol stores data codewords followed by Reed-Solomon error correction codewords. PLY1 partitions this space into two segments:

[ Public Byte Mode Payload ] [ Terminator (0000) ] [ Byte Alignment (0-7 bits) ]
[ 22-Byte PLY1 Header ] [ In-Padding Encrypted Payload ]
... [ End of Data Codewords ] ...
[ Reed-Solomon Parity Codewords (with optional Differential Modulation) ]

The PLY1 header is located immediately after the public payload’s 4-bit terminator and byte alignment padding. It is 22 bytes long and structured as follows:

Offset Field Name Length Type Description
0x00 magic 4 bytes ASCII Constant magic bytes: PLY1 (0x50 0x4C 0x59 0x31)
0x04 version 1 byte u8 Target QR Code version (1 to 40)
0x05 ec_level 1 byte u8 QR Error Correction level (L=0, M=1, Q=2, H=3)
0x06 mask 1 byte u8 Fixed QR pattern mask (0 to 7)
0x07 profile 1 byte u8 Profile: 1 (binary channel), 2 (extended channel)
0x08 public_len 2 bytes u16 (BE) Byte length of public payload
0x0A private_len 2 bytes u16 (BE) Byte length of plaintext private payload
0x0C padding_cap 2 bytes u16 (BE) Total padding byte capacity in data segment
0x0E diff_cap 2 bytes u16 (BE) Differential RS modulation byte capacity
0x10 nonce_prefix 6 bytes Binary 48-bit cryptographically random nonce prefix

  1. Standard Termination: Standard QR decoders parse data until they encounter the 4-bit terminator 0000 or exhaust the data capacity.
  2. Byte Alignment: If the terminator does not end on a byte boundary, up to 7 zero bits are appended to reach a full byte boundary.
  3. Padding Replacement: Standard QR encoding fills remaining data codewords with alternating 0xEC and 0x11 bytes. PLY1 replaces these dummy padding codewords with the 22-byte header and the primary encrypted payload chunk.

Standard QR scanners stop reading upon processing the terminator, completely ignoring the subsequent PLY1 header and ciphertext.